LWN.net Logo

squid: denial of service

Package(s):squid CVE #(s):CVE-2010-2951
Created:October 27, 2011 Updated:November 2, 2011
Description: From the CVE entry:

dns_internal.cc in Squid 3.1.6, when IPv6 DNS resolution is not enabled, accesses an invalid socket during an IPv4 TCP DNS query, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via vectors that trigger an IPv4 DNS response with the TC bit set.

Alerts:
Gentoo 201110-24 2011-10-26

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds